Available for New Projects

From code to
infrastructure —
I build and run
reliable systems.

Full-stack development, Linux infrastructure, networking engineering, AI integration, and DevOps — delivered by a single expert who stays until the job is done right.

3 YEARS EXPERIENCE
80+ SYSTEMS DEPLOYED
99.9% AVG UPTIME DELIVERED
system-check.sh
$ ./system-check.sh --full
→ Checking services...
nginx [running]
postgres [running]
redis [running]
docker [healthy]
 
→ Running security audit...
firewall: ufw active
ssh: key-auth only
ssl certs: valid 89d
 
→ Backup verification...
last snapshot: 4m ago
offsite sync: current
 
[ALL SYSTEMS NOMINAL]
$
PROFICIENT IN
Linux / Debian / Ubuntu / RHEL Docker / Kubernetes AWS / GCP / Hetzner Python / Node.js / Go Cisco / pfSense / OpenWRT PostgreSQL / Redis Nginx / Caddy / HAProxy

Deep expertise across
the full technical stack.

Six interconnected disciplines — each one backed by real-world production experience, not textbook knowledge.

Software & Web Development

Custom-built applications from landing pages to complex multi-tenant SaaS platforms. Built for performance, maintainability, and real users.

ReactNode.jsPython REST APIsPostgreSQLE-commerce
AI & Automation

Practical AI integration — chatbots, data pipelines, process automation, and ML prototypes that solve real business problems without hype.

OpenAILangChainn8n Data PipelinesAutomation
DevOps & Infrastructure

Cloud deployments, containerized environments, CI/CD pipelines, and observability stacks that let your team ship with confidence.

DockerTerraformGitHub Actions PrometheusGrafana
Networking Engineering

Network design, VLAN segmentation, firewall configuration, VPN deployment, and performance tuning for enterprise-grade reliability.

VLANBGP/OSPFpfSense WireGuardLoad Balancing
$_
Linux Systems Administration

Production Linux setup, security hardening, performance tuning, high availability configurations, and scripted automation that actually runs in production.

Debian/UbuntuRHELBash NginxHA/Clustering
🔒
Security & Hardening

System hardening, access control review, threat mitigation, configuration audits, and practical security posture improvements without over-engineering.

HardeningIAMFail2ban Audit LogsZero Trust

What each engagement
actually delivers.

Specific outcomes, not vague promises. Every service is scoped around your real situation.

01

Software &
Web Development

Whether you need a marketing site, a customer portal, or a full SaaS product, I build from the ground up with clean architecture, proper testing, and code you won't be embarrassed to hand to the next engineer.

  • Custom websites with CMS integration and fast load times
  • Full-stack applications: React/Vue frontend + Python or Node backend
  • SaaS platforms with multi-tenancy, billing, and user management
  • REST and GraphQL APIs — documented, versioned, and tested
  • E-commerce builds on custom or Shopify/Stripe foundations
  • Performance audits and optimization — Core Web Vitals to database queries
  • Legacy modernization and technical debt reduction
TYPICAL DELIVERABLES
Source code✓ Git repo
Documentation✓ Full docs
Test coverage> 70%
Deployment✓ Included
Lighthouse score> 90
Handover call✓ Recorded
02

AI & Automation

AI is most valuable when it's invisible — quietly handling repetitive work, surfacing the right information, or routing decisions correctly. I focus on practical integration that fits your existing workflow, not impressive demos that break in production.

  • LLM integration (OpenAI, Anthropic, Mistral) into existing products
  • Intelligent chatbots with retrieval-augmented generation (RAG)
  • Business process automation with n8n, Make, or custom scripts
  • ETL pipelines and data preprocessing for ML workloads
  • ML prototype development and evaluation
  • AI strategy consulting — where AI actually helps vs. where it doesn't
  • Workflow automation connecting your SaaS tools
TECH STACK
LLM ProvidersOpenAI · Anthropic · Mistral
OrchestrationLangChain · LlamaIndex
Automationn8n · Make · Airflow
Vector DBsPinecone · pgvector
Monitoring✓ Usage + cost tracking
03

DevOps & Cloud Infrastructure

Shipping code shouldn't be a manual process. I set up the infrastructure, pipelines, and observability so your team can deploy with confidence and sleep soundly when things go wrong.

  • Cloud provisioning on AWS, GCP, or bare-metal (Hetzner, OVH)
  • Docker and Docker Compose environments for dev/staging/prod parity
  • Kubernetes clusters with proper namespacing and resource limits
  • CI/CD pipelines in GitHub Actions, GitLab CI, or Drone
  • Monitoring with Prometheus + Grafana + alerting via PagerDuty or Slack
  • Automated backup systems with tested recovery procedures
  • Scaling strategies: horizontal, vertical, and cost-optimized
INFRASTRUCTURE AT A GLANCE
IaCTerraform / Ansible
Container runtimeDocker / containerd
OrchestrationK8s / Nomad / Compose
CI/CDGH Actions / GitLab
ObservabilityProm · Grafana · Loki
Backups✓ Tested & documented
04

Networking Engineering

From small office VLAN setups to multi-site enterprise networks, I design and implement networks that are secure by default, documented thoroughly, and easy for your team to manage.

  • Network architecture design for offices, data centers, and hybrid environments
  • VLAN design and 802.1Q trunk configuration
  • Firewall setup: pfSense, OPNsense, iptables, Fortinet
  • Site-to-site and remote access VPN: WireGuard, OpenVPN, IPSec
  • Routing protocols: BGP, OSPF, static routing, policy routing
  • Load balancing with HAProxy, Nginx, or hardware solutions
  • Network performance diagnostics and troubleshooting
  • Secure architecture review and zero-trust implementation
SUPPORTED PLATFORMS
FirewallspfSense · OPNsense · UFW
VendorsCisco · Ubiquiti · MikroTik
VPNWireGuard · OpenVPN · IPSec
RoutingBGP · OSPF · Static
Load balancersHAProxy · Nginx · Traefik
Diagrams✓ Full documentation
05

Linux Systems Administration

Linux is the backbone of most modern infrastructure. I configure, harden, and optimize Linux systems for production workloads — from single servers to clustered environments that need to stay up.

  • Fresh server setup with security baseline from day one
  • CIS benchmark hardening for Debian, Ubuntu, and RHEL
  • Nginx, Apache, and Caddy configuration and optimization
  • Reverse proxy and SSL/TLS certificate management
  • System performance tuning: kernel parameters, I/O schedulers, memory
  • Bash and Python automation scripts for operations
  • Log aggregation, rotation, and analysis
  • High availability setups: Keepalived, Pacemaker, Corosync
SYSTEM HEALTH — SAMPLE AUDIT
SSH hardening✓ Key-auth, no root
Firewall✓ UFW / nftables
Kernel updates✓ Unattended-upgrades
Fail2ban✓ Configured
Log rotation✓ Logrotate set
Backup cron✓ Verified daily
06

Security Services

Security isn't a product you buy — it's a practice you build. I help teams establish sensible, maintainable security practices that reduce real risk without grinding operations to a halt.

  • System and application hardening against common attack vectors
  • Access control review: least privilege, role-based, key management
  • Secrets management: Vault, environment isolation, credential rotation
  • Security audit support: evidence gathering, remediation guidance
  • Threat model reviews for web applications and APIs
  • Incident response support: containment, forensics, recovery
  • Best practice reviews aligned with OWASP, CIS benchmarks, SOC 2
SECURITY SCOPE
Network layer✓ Included
OS layer✓ Included
Application layer✓ Included
Access control✓ Included
Compliance prepSOC 2 / ISO 27001
Written report✓ Always delivered

Clear pricing,
no surprises.

Every project is scoped honestly. If something changes, we talk before the invoice does.

TIER 01
Starter

For individuals, early-stage startups, and straightforward single-service projects.

$800
starting from / project
  • Single-service scope (e.g. landing page, VPS setup, Linux hardening)
  • 1 revision round
  • Basic documentation
  • Email support for 14 days post-delivery
  • Delivery: 3–10 business days
  • Priority scheduling
  • Ongoing maintenance
Get a Quote →
TIER 03
Infrastructure

For scaling platforms, complex network builds, enterprise setups, and multi-system deployments.

$6,000
starting from / project
  • Complex, multi-component infrastructure builds
  • Full architecture design and documentation
  • Unlimited revisions within scope
  • 60 days post-delivery support
  • Runbooks, disaster recovery plans
  • Priority response < 4 hours during project
  • Delivery: 4–12 weeks
Request a Scoping Call →

Consulting & Hourly

For advisory work, incident support, architecture reviews, and ongoing problem-solving.

Standard consulting rate $120 / hour
Incident response (urgent) $180 / hour
Architecture review (half-day) $600 flat
Architecture review (full-day) $1,100 flat
Training / workshop (per session) $400 flat

Monthly Retainers

Ongoing support, monitoring, and priority access — ideal for businesses that don't want to manage this alone.

Essentials — 5h/month + monitoring $450 / mo
Growth — 15h/month + priority support $1,200 / mo
Partner — 30h/month + 4h SLA $2,200 / mo
Retainer includes Updates · Alerts · Reports
Response time (Partner SLA) ≤ 4 hours

Built for your situation,
not a template.

The problems I solve are different across teams. Here's how I typically help.

🚀
Startups Moving Fast

You've validated your idea and need real infrastructure fast — not a tutorial setup. I help early teams build on a solid foundation so the architecture doesn't collapse when you scale. MVP to production, done right from the start.

🏢
Small & Mid-size Businesses

You have systems running but no one who truly owns them. I become your on-call technical expert — keeping things updated, secure, and reliable so you can focus on the business, not the servers.

📈
Scaling Platforms

You're growing faster than your infrastructure can handle. Database queries are slow, deploys are risky, and costs are climbing. I audit the bottlenecks, redesign the problem areas, and build a path to sustainable scale.

🔥
Infrastructure Rescue

Something broke, or you inherited a system nobody fully understands. I come in, document what exists, stabilize what's unstable, and build a recovery plan — calmly and methodically, without making things worse.

A clear process
from first contact to delivery.

No ambiguity about what happens next. Every engagement follows the same disciplined approach.

STEP 01
Discovery Call

We talk through your situation, goals, constraints, and timeline. I ask the uncomfortable questions upfront so there are no surprises later. Free, 30–45 minutes.

STEP 02
Scoped Proposal

A written proposal with a clear scope, deliverables, timeline, and fixed price. What's in, what's out, and what happens if scope changes. No hidden fees.

STEP 03
Execution

I work systematically with regular updates. You're not left wondering what's happening. Testing and review happen continuously, not just at the end.

STEP 04
Delivery & Handover

A recorded walkthrough, full documentation, and anything else your team needs to own and operate what was built. No black boxes.

STEP 05
Ongoing Support

Post-delivery support is included in every project. For ongoing needs, a retainer keeps me available as your systems grow and evolve.

LocationRemote · Albania
Experience3 years
FocusInfrastructure & Dev
AvailabilityOpen for projects
LanguagesEnglish · Albanian · German
TimezoneUTC±flexible

I'm a systems thinker who writes code, designs networks, and keeps things running.

Over the past 3 years I've built and maintained systems across every layer of the stack — from writing React components and Python services to configuring BGP routing and hardening production Linux servers. That breadth isn't an accident: I genuinely find the whole stack interesting.

I work best with teams who want a technically credible partner, not just a task executor. I'll tell you when your plan has a flaw, suggest a simpler approach when one exists, and flag risks before they become incidents. I take delivery seriously — documentation, tests, and runbooks are not afterthoughts.

I've consulted for funded startups, managed infrastructure for SaaS companies, designed office networks for enterprises, and helped engineering teams recover from serious production incidents. The common thread is that I show up, do the work properly, and leave things better than I found them.

LANGUAGES

  • Python
  • Node.js / TypeScript
  • Go
  • Bash / Shell
  • SQL

INFRASTRUCTURE

  • Terraform · Ansible
  • Docker · Kubernetes
  • AWS · GCP · Hetzner
  • Prometheus · Grafana

NETWORKING

  • pfSense · OPNsense
  • Cisco · Ubiquiti
  • WireGuard · OpenVPN
  • BGP · OSPF

LINUX

  • Debian · Ubuntu · RHEL
  • Nginx · Caddy
  • Systemd · Cron
  • CIS Hardening

What clients say.

Real feedback from teams I've worked with.

Tomas took our staging environment — a pile of manually-configured servers with no documentation — and transformed it into a fully automated, monitored infrastructure in four weeks. We've had zero unplanned downtime since.

🧑
— Rajmond Lika CTO · SaaS Company

I needed someone who understood both the application layer and the network layer. Tomas diagnosed our latency issue in hours — it was a misconfigured firewall rule causing retransmissions that nobody had ever tied to performance.

👩
— Derek Ainsley VP Engineering · E-commerce Platform

Working with Tomas feels like having a senior engineer on call. The communication is clear, the documentation is thorough, and the work holds up under scrutiny. We've renewed our retainer three times.

🧑
— Florian Beck Founder · B2B Software Startup

Common questions.

Do you work with a team or is it just you?
It's primarily me — that's intentional. You're not getting a junior contractor assigned after a sales call. For larger projects, I may bring in trusted specialists (e.g. a designer or second engineer) but I remain the primary point of contact and technical accountability throughout.
How are projects priced — is it hourly or fixed?
Most projects are fixed-price against a scoped deliverable list. This protects both of us: you know the cost upfront, and I have a clear success criteria. Consulting, advisory work, and retainer support are hourly or monthly flat-rate. I never start work without an agreed scope and payment terms.
What if my project grows beyond the original scope?
Scope changes happen. When they do, we discuss the impact honestly before any additional work begins. I'll tell you whether something is a minor addition I can absorb, or whether it warrants a formal change order. No surprise invoices.
How quickly can you start a new project?
Availability varies. For standard projects, I typically have a 1–3 week lead time. For urgent infrastructure or incident response, I maintain limited slots for immediate engagement. Contact me and I'll give you an honest answer within 24 hours.
Do you offer any guarantees?
I guarantee that I'll deliver what's in the scope document, with the quality standards we agree on. If something I built doesn't work as specified, I'll fix it at no charge. I can't guarantee third-party services or systems outside my control — but I'll be transparent about those risks upfront.
Can you work with my existing team?
Yes. I regularly embed alongside in-house engineering teams — reviewing PRs, pairing on complex problems, advising on architecture, or taking ownership of a specific layer (e.g. infrastructure) while the team handles application code. I adapt to your workflow.
What information do you need to provide a quote?
A brief description of the problem or goal, your current setup (even roughly), your timeline, and any constraints (budget, tech stack, compliance requirements). The more context you give in the intake form, the faster I can come back with something accurate.

Let's talk about your project.

Fill out the form with as much context as you can. I'll review it and respond within 1 business day with either a direct answer or a request to schedule a call.

Email tomascamaj2010@gmail.com
Response Within 1 business day
Timezone Flexible / remote-first
Currently accepting new projects